Forum Discussion

Anthony_BRISSON's avatar
Anthony_BRISSON
Icon for Nimbostratus rankNimbostratus
Jul 25, 2009

firepass network access to corporate VLAN

Hi everyone,

 

 

I have a question about the network access mode of the firepass vpn solution.

 

If the firepass have an interface on our coporate VLAN (subnet : 192.168.100.0/24), is it possible to connect users directly (with the network acces) to this vlan without NAPT (with the same ippool than the corporate vlan but with different ip address range).

 

For information the default gateway of the corporate VLAN is not the firepass.

 

 

Thanks in advance for your answer.

 

 

1 Reply

  • It does not look like it.

     

     

    Log on to your Firepass admin interface then go to Network Access -> Global settings -> and click "Help" to see the help text for this topic. It is "Deciding on NAPT or virtual subnet".

     

     

    The help text indicates that you can turn off NAPT, but the Firepass won't simply bridge the Network Access users onto your corporate LAN. If you use the same address pool for the Firepass as you have on your LAN, you will have problems. You could on the other hand assign a new subnet to Network Access users and allow access to the LAN from that new subnet.